Indirect prompt injection is the number one security vulnerability in autonomous AI systems: an untrusted web page, email, or customer ticket contains hidden instructions that hijack the agent tool execution. We explain the dual-LLM air-gap defense pattern.
Separating untrusted data processing from privileged action orchestration via deterministic boundary validators.